By EJN Labs · 20 Jul 2026 · 8 min read
FCA op res penetration testing is not a named rulebook requirement. The FCA’s operational resilience rules require scenario testing: evidence that important business services stay within impact tolerances under severe but plausible disruption, including cyber attack. Penetration testing is the standard technical evidence behind that claim. Most firms budget £4,800 to £8,400 for a focused engagement, 4 to 6 days at £1,200 to £1,400 per day.
Why operational resilience changed the testing conversation
Before the FCA’s operational resilience regime, penetration testing in financial services was largely a security team purchase. The rules moved the question up a level: the board must now state, in a written self-assessment, that the firm’s important business services can withstand severe but plausible disruption. A cyber attack that takes down payments, onboarding or trade execution is exactly the kind of disruption the Financial Conduct Authority expects firms to have tested against.
That changes what the report has to prove. A compliance director or operational resilience lead needs evidence that the technical routes an attacker would use to breach an impact tolerance have been probed by an independent party, and that the results fed back into the scenario testing programme.
What the FCA operational resilience rules actually require
The regime, set out in the FCA’s policy statement PS21/3 and the SYSC 15A chapter of the FCA Handbook, applies to banks, building societies, PRA-designated investment firms, insurers, enhanced scope SM&CR firms, and payment and e-money institutions. The transition period ended on 31 March 2025, so in-scope firms are now expected to be operating within their impact tolerances, not merely working towards them.
The core obligations are:
- Identify your important business services: the services which, if disrupted, would cause intolerable harm to consumers or risk to market integrity.
- Set an impact tolerance for each one: the maximum tolerable level of disruption, usually expressed as a time limit.
- Map the people, processes, technology, facilities and third parties each service depends on.
- Carry out scenario testing to confirm the service can stay within its impact tolerance under severe but plausible scenarios.
- Maintain a self-assessment document, approved by the board, recording all of the above and the lessons learned.
Cyber attack sits squarely inside “severe but plausible”. A firm that has only rehearsed an outage or supplier failure, and never tested whether an attacker could reach the systems behind an important business service, has an obvious gap in its scenario coverage.
Does the FCA mandate a penetration test? An honest answer
No. The rules mandate scenario testing; they do not name penetration testing as a required control, and there is no clause that says “commission an annual pen test”. Any provider telling you otherwise is overselling.
What the rules do demand is credible evidence. If your self-assessment claims an intrusion scenario would not breach your impact tolerance, a supervisor is entitled to ask how you know. Tabletop exercises test decision-making; they do not test whether your perimeter, applications or remote access can actually be breached. Penetration testing is how firms turn “we believe the service is defensible” into “an independent, CREST-accredited firm attempted the attack paths and here is what happened”. For mature programmes, a red team exercise rehearses the full scenario end to end, detection and response included.
In practice, most in-scope firms treat penetration testing as the technical layer of scenario testing: the pen test validates the attack surface, the scenario exercise validates the recovery, and the self-assessment cites both.
What to test: scoping around important business services
The regime gives you the scoping method for free: start from each important business service and its mapped dependencies, then test the technology in that chain. When we scope these engagements at EJN Labs, we ask for the firm’s service mapping first, because it tells us precisely which systems carry regulatory weight. Typical components:
Payment and transaction platforms
The systems that move money are almost always important business services. Testing covers the application logic, the APIs that connect to schemes, banks and open banking providers, and the authentication and authorisation controls around them.
Customer-facing web and mobile channels
Portals, onboarding journeys and mobile apps are both an attack surface and, for many firms, the service itself. If customers cannot log in, the impact tolerance clock is running.
Cloud estate and third parties
Most regulated firms now run important business services on AWS, Azure or Google Cloud. A cloud penetration test reviews identity, network segmentation and configuration, which is where real intrusions in financial services usually begin. Where a critical outsourced provider is in the dependency chain, your contract should give you the right to test or to receive their test results.
External perimeter and remote access
External infrastructure testing checks every internet-facing asset: VPNs, mail gateways, admin interfaces and forgotten subdomains. These are the entry points in the majority of severe but plausible cyber scenarios worth rehearsing.
How an engagement runs
Scoping starts from your important business services map and agrees the systems, test windows and any change freeze constraints; regulated firms often need testing outside trading hours or against a production-like environment. Testing is performed by UK-based testers under CREST methodology, with an escalation route so any critical finding reaches your team the day it is found. Reporting serves two audiences: a technical annex for the engineers fixing the findings, and a summary mapping each significant finding to the affected business service, which is the part that goes into the self-assessment. A retest confirms the fixes closed the gaps. Our penetration testing checklist covers what to prepare before day one.
What it costs and how scope drives the price
UK penetration testing is priced by effort. Day rates at CREST-accredited firms typically run £1,200 to £1,400, and the number of days is driven by the size and complexity of what sits behind each important business service. Typical ranges:
| Scope | Typical effort | Typical cost |
|---|---|---|
| External infrastructure and remote access | 3 to 5 days | £3,600 to £7,000 |
| Web application or API behind one important business service | 4 to 6 days | £4,800 to £8,400 |
| Cloud configuration review plus supporting infrastructure | 5 to 7 days | £6,000 to £9,800 |
| Scenario-led testing across several services | 8 to 12 days | £9,600 to £16,800 |
These are typical UK market ranges rather than a quote; the fastest way to get an exact figure is the quote form. For what moves the price, see our guide to penetration testing costs in the UK. Testing scoped around business services usually costs less than a “test everything” exercise, because the dependency mapping you already did for the FCA removes the discovery work.
How EJN Labs approaches FCA operational resilience testing
EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with all testing delivered by UK-based testers. For regulated firms we scope from the important business services map rather than the asset register, and we report findings against the affected service, not just the affected host, so the results drop into the board-approved self-assessment without translation. We also flag where a finding suggests a scenario your programme has not yet rehearsed, because the FCA expects scenario testing to evolve with lessons learned. Our overview of cyber security for financial services covers the wider control landscape beyond testing.
Frequently Asked Questions
Does the FCA require penetration testing under its operational resilience rules?
Not by name. SYSC 15A requires scenario testing against severe but plausible disruption, and cyber attack is an expected scenario. Penetration testing is the standard technical evidence that the attack paths into an important business service have been independently tested, so most in-scope firms include it in their testing programme and cite it in the self-assessment document.
What does penetration testing for FCA operational resilience cost?
UK day rates at CREST-accredited firms typically run £1,200 to £1,400. A web application or API behind one important business service is usually 4 to 6 days, so £4,800 to £8,400. External infrastructure runs 3 to 5 days, £3,600 to £7,000, and scenario-led testing across several services runs 8 to 12 days, £9,600 to £16,800. Exact pricing depends on scope.
Which firms are in scope of the FCA operational resilience rules?
Banks, building societies, PRA-designated investment firms, insurers, enhanced scope SM&CR firms, and payment and e-money institutions. The transition period ended on 31 March 2025, so in-scope firms are now expected to operate within their impact tolerances and to hold current testing evidence, not a plan to obtain it.
How often should a regulated firm run a penetration test?
Annually as a baseline, plus after material change to any system supporting an important business service, such as a new payment platform, a cloud migration or a major release. The FCA expects scenario testing to be a continuing programme rather than a one-off, and stale technical evidence weakens the self-assessment the board has to approve.
What testing evidence should go in the self-assessment document?
The scenarios tested, the method and independence of the testing, findings mapped to the affected important business services, remediation and retest results, and the lessons learned that changed your controls or your scenario set. A penetration test report that maps findings to services, plus a retest certificate, slots directly into that structure.
Get testing evidence your self-assessment can stand on
If your next self-assessment review needs independent technical evidence behind your cyber scenarios, we can scope a test around your important business services in one call. EJN Labs delivers CREST-accredited penetration testing with UK-based testers and reporting written for both engineers and the board. Request a quote and you will have a scoped proposal within one working day.




Leave a Reply